Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that solves one vulnerability can now be installed.. # Security update for krb5 Announcement ID: SUSE-SU-2026:20314-1 Release Date: 2025-09-22T08:44:49Z Rating: moderate References: * bsc#1241219 Cross-References: * CVE-2025-3576 CVSS scores: * CVE-2025-3576 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2025-3576 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2025-3576 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N Affected Products: * SUSE Linux Micro 6.0 * SUSE Linux Micro Extras 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for krb5 fixes the following issues: * CVE-2025-3576: Fixed Kerberos RC4-HMAC-MD5 Checksum Vulnerability (bsc#1241219) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro Extras 6.0 zypper in -t patch SUSE-SLE-Micro-Extras-6.0-469=1 ## Package List: * SUSE Linux Micro Extras 6.0 (aarch64 ppc64le s390x x86_64) * krb5-mini-debuginfo-1.20.1-7.1 * krb5-mini-debugsource-1.20.1-7.1 * krb5-mini-1.20.1-7.1 ## References: * https://www.suse.com/security/cve/CVE-2025-3576.html * https://bugzilla.suse.com/show_bug.cgi?id=1241219 . A moderate security update for krb5 addresses a checksum flaw, ensuring improved system integrity. Learn more!. SUSE Linux, krb5 update, checksum security, SUSE attack vector integrity. . LinuxSecurity.com Team
* bsc#1241219 Cross-References: * CVE-2025-3576 . # Security update for krb5 Announcement ID: SUSE-SU-2025:20719-1 Release Date: 2025-09-22T08:42:37Z Rating: moderate References: * bsc#1241219 Cross-References: * CVE-2025-3576 CVSS scores: * CVE-2025-3576 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2025-3576 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2025-3576 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N Affected Products: * SUSE Linux Micro 6.0 * SUSE Linux Micro Extras 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for krb5 fixes the following issues: * CVE-2025-3576: Fixed Kerberos RC4-HMAC-MD5 Checksum Vulnerability (bsc#1241219) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-469=1 * SUSE Linux Micro Extras 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-469=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * krb5-client-debuginfo-1.20.1-7.1 * krb5-debugsource-1.20.1-7.1 * krb5-1.20.1-7.1 * krb5-client-1.20.1-7.1 * krb5-debuginfo-1.20.1-7.1 * SUSE Linux Micro Extras 6.0 (aarch64 s390x x86_64) * krb5-mini-debuginfo-1.20.1-7.1 * krb5-mini-1.20.1-7.1 * krb5-mini-debugsource-1.20.1-7.1 ## References: * https://www.suse.com/security/cve/CVE-2025-3576.html * https://bugzilla.suse.com/show_bug.cgi?id=1241219 . SUSE's Security update addresses a moderate checksum issue in krb5. Critical for maintaining system integrity and security.. SUSE Linux, krb5 update, checksum vulnerability, security advisory. . LinuxSecurity.com Team
Isaac Boukris and Andrew Bartlett discovered that the S4U2Self Kerberos extension used in Samba's Active Directory support was susceptible to man-in-the-middle attacks caused by incomplete checksum validation. . Package : samba Version : 2:4.2.14+dfsg-0+deb8u13 CVE ID : CVE-2018-16860 Isaac Boukris and Andrew Bartlett discovered that the S4U2Self Kerberos extension used in Samba's Active Directory support was susceptible to man-in-the-middle attacks caused by incomplete checksum validation. For Debian 8 "Jessie", this problem has been fixed in version 2:4.2.14+dfsg-0+deb8u13. We recommend that you upgrade your samba packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Enhance your Samba installation to address man-in-the-middle vulnerabilities by applying the most recent security patch for Debian 8.. Samba Security Update, Debian LTS, Kerberos Vulnerability. . LinuxSecurity.com Team
Isaac Boukris and Andrew Bartlett discovered that the S4U2Self Kerberos extension used in Samba's Active Directory support was susceptible to man-in-the-middle attacks caused by incomplete checksum validation. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4443-1
This update does sanity checking when an application passes in a checksum to verify. Before this release, applications could pass in non-hex values for the checksum, which could cause zchunk to crash. Now non-hex values will be rejected.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-7d138cfd7b 2018-11-07 02:39:18.191860 --------------------------------------------------------------------------------Name : zchunk Product : Fedora 29 Version : 0.9.14 Release : 1.fc29 URL : https://github.com/zchunk/zchunk Summary : Compressed file format that allows easy deltas Description : zchunk is a compressed file format that splits the file into independent chunks. This allows you to only download the differences when downloading a new version of the file, and also makes zchunk files efficient over rsync. zchunk files are protected with strong checksums to verify that the file you downloaded is in fact the file you wanted. --------------------------------------------------------------------------------Update Information: This update does sanity checking when an application passes in a checksum to verify. Before this release, applications could pass in non-hex values for the checksum, which could cause zchunk to crash. Now non-hex values will be rejected. --------------------------------------------------------------------------------ChangeLog: * Thu Nov 1 2018 Jonathan Dieter - 0.9.14-1 - Sanity check hex hashes passed in as an option * Mon Oct 8 2018 Jonathan Dieter - 0.9.13-1 - Add read support for zchunk files with optional flags - Fix tests for zstd-1.3.6 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-7d138cfd7b' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
globus-ftp-client * Adapt to Perl 5.26 - POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don't attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data from public. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-0eea793538 2017-07-14 11:45:23.814507 --------------------------------------------------------------------------------Name : globus-gass-copy Product : Fedora 26 Version : 9.27 Release : 1.fc26 URL : http://toolkit.globus.org/ Summary : Globus Toolkit - Globus Gass Copy Description : The Globus Toolkit is an open source software toolkit used for building Grid systems and applications. It is being developed by the Globus Alliance and many others all over the world. A growing number of projects and companies are using the Globus Toolkit to unlock the potential of grids for their cause. The globus-gass-copy package contains: Globus Gass Copy --------------------------------------------------------------------------------Update Information: globus-ftp-client * Adapt to Perl 5.26 - POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don't attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data from public handle (9.26) * Prevent some race conditions (9.27) globus-gram-client * GT6 update globus-gram-job-manager * Default to running personal gatekeeper on an ephemeral port globus-gram-job-manager-condor * Make noarch build arch independent globus-gridftp-server * New error message format (12.0) * Configuration database (12.0) *Better delay for end of session ref check (12.1) * Fix tests when getgroups() does not return effective gid (12.2) globus-gssapi-gsi * Don't unlock unlocked mutex (12.14) * Remove legacy SSLv3 support (12.15) * Test fixes (12.16/12.17) * Drop patch globus-gssapi-gsi-mutex-unlock.patch (fixed upstream 12.14) globus-io * Remove legacy SSLv3 support globus-net-manager * Fix .pc typo * Drop patch globus-net-manager-pkgconfig.patch (fixed upstream) globus-xio * Don't rely on globus_error_put(NULL) to be GLOBUS_SUCCESS (5.15) * Fix crash in error handling in http driver (5.16) globus-xio-gsi-driver * Fix crash when checking for anonymous GSS name when name comparison fails globus-xio-pipe-driver * Fix .pc typo globus-xio-udt-driver * Don't force --static flag to pkg-config * Drop some BuildRequires no longer needed with above change * Fix undefined symbols during linking myproxy * Fix error check (6.1.26) * Remove legacy SSLv3 support (6.1.27) --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade globus-gass-copy' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
This posting gives the correct md5 sums for the previous kernel update.. The recent kernel update announcement contained md5sums of the unsigned kernels. After they were signed, the RPMs changed, which made the md5sums useless. Here is the list of correct md5sums. Apologies, Dave 589a54fd2cced8d92a56ae20ed45c4d0 x86_64/kernel-2.6.6-1.435.2.3.x86_64.rpm 892d973313300866b055f2bd34555036 x86_64/kernel-smp-2.6.6-1.435.2.3.x86_64.rpm 14a7b5561856a412d264350590f6d442 x86_64/kernel-debuginfo-2.6.6-1.435.2.3.x86_64.rpm 25571b4f821532794d0370e10b33fade noarch/kernel-sourcecode-2.6.6-1.435.2.3.noarch.rpm 899f693bad1197005b8294825141a2f7 noarch/kernel-doc-2.6.6-1.435.2.3.noarch.rpm 1781389f2359206f59ef5410ccecd278 ppc/kernel-2.6.6-1.435.2.3.ppc.rpm 71a19f0e0ab1c3c8d8a4342c4ea0bd5e ppc/kernel-debuginfo-2.6.6-1.435.2.3.ppc.rpm e3d8299729b73d85e6c538248d04719c SRPMS/kernel-2.6.6-1.435.2.3.src.rpm fa099f202ec122e59c585a13516ee5dd i586/kernel-2.6.6-1.435.2.3.i586.rpm 7a6f7e7a4240f69aaef161f9965c50a1 i586/kernel-smp-2.6.6-1.435.2.3.i586.rpm 1d87ad4cbf5718a60205a1cc3917e8f2 i586/kernel-debuginfo-2.6.6-1.435.2.3.i586.rpm 8a5eb4d627036d2fa1b012a2277faa3e i686/kernel-2.6.6-1.435.2.3.i686.rpm 5de1c6ae7c1dbc28e259d0ef0ce98993 i686/kernel-smp-2.6.6-1.435.2.3.i686.rpm d5afac6cc9ca2b644a56b070731dd405 i686/kernel-debuginfo-2.6.6-1.435.2.3.i686.rpm . Corrected sha256 checksums for the newest kernel version are provided to ensure software integrity and security.. Kernel Update, MD5 Checksum, Software Integrity, Fedora Security. . Severity: Informational. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.